logo

Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access

ID: 8d9bf98e-d4d6-59a2-8489-c7005947725c

STIX ID: report--8d9bf98e-d4d6-59a2-8489-c7005947725c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Ddos

...
...

Apache Polaris released a security update (1.4.1) addressing four important vulnerabilities that let authenticated low-privileged users obtain delegated cloud storage credentials for attacker-controlled locations, potentially enabling reading, listing, creating, or deleting data across AWS S3 and Google Cloud Storage. The flaws (CVE-2026-42809 through CVE-2026-42812) stem from premature credential vending, unescaped wildcard and quote characters in resource restrictions, and a metadata-path validation bypass; administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.